TA570 is a financially motivated cybercrime threat actor tracked as a prolific distributor of QakBot, also known as Qbot, QuakBot, Pinkslipbot, and Oakbot. Active since at least 2018, TA570 is best known as an initial-access and malware delivery affiliate within the broader QakBot ecosystem rather than as the core malware developer itself. The actor has repeatedly used large-scale phishing and malspam operations to deliver QakBot into enterprise environments, after which downstream activity has included credential theft, email theft, reconnaissance, lateral movement support, persistence, and delivery of follow-on payloads such as Cobalt Strike and ransomware. TA570 is strongly associated with email thread hijacking campaigns that reuse existing conversations to increase credibility. Delivery chains attributed to the actor have used malicious attachments and links, including HTML smuggling, ZIP archives, disk images, Windows shortcut files, OneNote documents, and Microsoft Word documents. TA570 has also been observed abusing CVE-2022-30190 (Follina) in phishing campaigns to deliver QakBot. In multiple campaigns, the actor used multi-stage infection chains in which user interaction launched a shortcut or script that executed a QakBot DLL through legitimate Windows utilities. Operationally, TA570 has been linked to compromised websites and file-hosting services used to stage payloads. The actor is sometimes referred to as the “presidents” affiliate because campaign identifiers associated with its QakBot activity have used names of U.S. presidents. TA570 is widely regarded as one of the most active QakBot affiliates and has been cited alongside other major malware distributors such as TA577 and TA551. Intrusions enabled by TA570-delivered QakBot have been associated with follow-on ransomware activity, including ProLock and Egregor, and broader reporting has linked the QakBot ecosystem to additional ransomware operations. TA570 therefore fits the profile of an initial access facilitator in the cybercrime ecosystem, with primary value derived from establishing footholds that can be monetized through credential theft, resale of access, or enabling later-stage extortion operations.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
10 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
1 CVE this actor has used in observed campaigns. 1 of them exploited in the wild.
150 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
10 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Associated with campaigns using Qakbot as an initial access payload, including recent OneNote-based phishing delivery discussed in the report.
Referenced in connection with LNK-based malware distribution campaigns.
Referenced as a malware distributor associated with stolen-email thread hijacking for phishing delivery.
E-crime threat cluster associated with orchestrating Qakbot activity (historically a banking trojan/loader ecosystem).
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.